PT-2017-6688 · Canonical · Usb-Creator

Tavis Ormandy

·

Publicado

2015-04-23

·

Atualizado

2017-10-11

·

CVE-2015-3643

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions usb-creator versions prior to 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS usb-creator versions prior to 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS usb-creator versions prior to 0.2.62ubuntu0.3 on Ubuntu 14.10 usb-creator versions prior to 0.2.67ubuntu0.1 on Ubuntu 15.04
Description The issue allows local users to gain privileges by leveraging a missing call to check polkit for the KVMTest method.
Recommendations For usb-creator version prior to 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, update to version 0.2.38.3ubuntu0.1 or later. For usb-creator version prior to 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, update to version 0.2.56.3ubuntu0.1 or later. For usb-creator version prior to 0.2.62ubuntu0.3 on Ubuntu 14.10, update to version 0.2.62ubuntu0.3 or later. For usb-creator version prior to 0.2.67ubuntu0.1 on Ubuntu 15.04, update to version 0.2.67ubuntu0.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3643
USN-2576-1
USN-2576-2

Produtos afetados

Usb-Creator